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DETAILED ACTION 



1. 



Claims 1-20 are pending. 



Specification 



2. The use of the trademark JAVA / JAVA Script has been noted in this application. It 
should be capitalized wherever it appears and be accompanied by the generic terminology. 

Although the use of trademarks is permissible in patent applications, the proprietary 
nature of the marks should be respected and every effort made to prevent their use in any manner 
which might adversely affect their validity as trademarks. 



Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or 
any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and 
requirements of this title. 



4. Claims 1-14 are rejected under 35 U.S.C. 101 because the claimed invention is directed 
to non-statutory subject matter. Claim 1 recites "A computer program product, tangibly 
embodied in an information carrier. . ." The Specification, at page 11, line 30, defines a computer 
program product to include a 'propagated signal', which is a non statutory embodiment. Claim 1 
may be amended to recite "A computer program storage p roduct, for generating. . . 

5. Claims 18-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed 
to non-statutory subject matter. Claim 18 recites a system comprising only software. Software 
per se is non statutory. Claim 18 may be amended to recite . .the system comprising: a client 
and server computer device: ..." 



Claim Rejections - 55 USC § 101 



3. 



35 U.S.C. 101 reads as follows: 
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Claim Rejections - 35 USC § 102 

6. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the 
basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in (1) an application for patent, published under section 122(b), by another Filed 
in the United States before the invention by the applicant for patent or (2) a patent granted on an application for 
patent by another filed in the United States before the invention by the applicant for patent, except that an 
international application filed under the treaty defined in section 351(a) shall have the effects for purposes of this 
subsection of an application filed in the United States only if the international application designated the United 
States and was published under Article 21(2) of such treaty in the English language. 

7. Claims 1, 2, and 4-20 are rejected under 35 U.S.C. 102(e) as being anticipated by US 
Patent Application Publication US 2004/0064731 Al to Nguyen et al. 

Per claim 1: 

A computer program product, tangibly embodied in an information carrier, for generating an 
integrated trace output file on a system having a first computing device and a second computing 
device, the computer program product being operable to cause data processing apparatus to: 
Nguyen: FIG. 2, #106, Client Agents, #108, Server Agents [0033], monitor and evaluate events 
[[0038], The analysis and reporting component 120 provides tools to review and synthesize the 
data collected. 

-generate a first trace output at the first computing device; 
-receive a second trace output from the second computing device; 

-generate an integrated trace output file by combining the second trace output with the first trace 
output. 
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Nguyen: [0039], reports may be generated by the analysis and reporting component 120 for the 
IN as a whole (first trace, second trace). Alternatively, reports may be generated for particular 
subsets of the IN. . .particular monitoring agents (first, second). . .generate reports automatically 
using predefined reporting formats [0054], A determination is then made as to whether the event 
is suitable for aggregation (combining trace outputs) 

Per claim 2: 

-instructions to: provide an agent for detecting an event at the second computing device. 
Nguyen: [0027], monitoring agents to monitor the monitored elements. . .client agents 106 

Per claim 4: 

-instructions to: identify a severity level for event detection at the first computing device; 
-detect an event having the identified severity level. 

Nguyen: [0033], The assessment prediction component (116) is used to characterize an event or 
sequence of events against predefined monitoring and response rules. . .may use appropriate 
mathematical techniques [0057], The response management component may respond to an event 
of set of events at one of several levels (severity level).. 

Per claim 5: 

-the severity level indicates whether the first trace output comprises an error message, a warning 
message, an information message, or a debug message. 
Nguyen: [0057], inform level, enforce level, or prevent level. 
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Per claim 6: 

-instructions to: identify a severity level for event detection at the second computing device; 
-detect an event having the identified severity level 

See rejection of claim 4 above. Monitors are at each (second) computing device. 
Per claim 7: 

-the severity level indicates whether the second trace output comprises an error message, a 
warning message, an information message, or a debug message. 
Nguyen: [0057], inform level, enforce level, or prevent level. 

Per claim 8: 

-instructions to: receive an active component trace output from the second computing device. 
Nguyen: [0049], client agents on a corresponding device (second) [0050], data collected by a 
client agent . . .sent to the core system. 

Per claim 9: 

-instructions to: combine the active component trace output with the first trace output. 
Nguyen: [0054], event aggregation 

Per claim 10: 

-the second trace output includes an active component trace output generated at the second 
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computing device. 

Nguyen: [0053], monitored elements are monitored by monitoring agents. . .when an event 
associated with a particular monitored element (second computing device) occurs, a monitoring 
agent obtains event information (active component trace output) 

Per claim 1 1 : 

-the first computing device is a server and the second computing device is a client. 

Nguyen: [0048], server agent is located on a server [0049], client agent & client device [0053], 

server agents and client agents 

Per claim 12: 

-instructions to: display the integrated trace output on the second computing device. 
Nguyen: [0043], GUI display in toolkit component 126 

Per claim 13: 

-instructions to display the integrated trace output in a separate browser window. 
Nguyen: [0043], GUI display in toolkit component 126 

Per claim 14: 

-instructions to generate the integrated trace output file comprise instructions to combine the 
second trace output with the first trace output in a chronological order. 
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Nguyen: [0033], characterize an event or sequence of events (chronological order) using rules 
and mathematical techniques [0054], combine the event with other events. 

Per claim 15: 

A method comprising: 

-detecting an event at a client; 

Nguyen: [0029], event detected in association with a monitored element (event detected at 
client) 

-generating a client-side trace output in response to the event detection at the client; 
Nguyen: [0027], client agents which receive data collected from the set of monitored system 
devices. 

-transmitting the client-side trace output to a server for integration with a server-side trace 
output. 

Nguyen: [0032], correlation and aggregation component is used to combine a series of events 
into one single aggregated event 

Per claim 16: 

-the event at the client device occurs while a user is interacting with an application program 
executing on the server. 

Nguyen: [0015], protecting an Information network (IN) using an Integrated Security 
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Administrator (ISA), comprising obtaining a plurality of events on the IN [0024], An Integrated 
Security Administrator (ISA) (application program executing on the server) for managing and/or 
protecting information and assets of an enterprise's Informational Network (IN). [0025], The 
ISA may also interact with external entities, such as managed services. . .computer 
security. . .computer network security components [0026], The ISA includes one or more 
monitored elements. . .system devices. . .network devices. . . 

Nguyen: [0027], client agents which receive data collected (events at client device) from the set 
of monitored system devices 

Per claim 17: 

-detecting an event at the server while the user is interacting with the application program; 
-generating the server-side trace output in response to the event detection at the server; 
-integrating the server-side trace output with the client-side trace output to generate a single trace 
output file. 

Nguyen: [0066], Enterprise's computer network firewalls and IDS's (Intrusion Detection 
Systems) receive hundreds of different attacks, recognize and react. . .correlation and aggregation 
component and the analysis and reporting component perform correlation ..The response 
management component coordinates a single, distributed response that affects the monitored 
elements... 

Per claim 18: 

A system for generating an integrated trace output file, the system comprising: 
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a client agent including: 

-a detection module configured to detect an event at a client; 

-a generation module configured to generate a client-side trace output in response to the event 
detection at the client; 

-a communication module configured to transmit the client-side trace output to a server; 
a server agent including: 

-a detection module configured to detect an event at the server; 

-a generation module configured to generate a server-side trace output in response to the event 
detection at the server; 

-a communication module configured to receive the client-side trace output from the client; 
-an integration module configured to generate an integrated trace output file by combining the 
client-side trace output with the server-side trace output. 

Nguyen: [0027], monitoring agents to monitor the monitored elements. . .client agents 106, 
server agents 108, receives data collected (generate trace output) from the set of monitored 
applications and the set of monitored network devices. [0029], correlation and aggregation 
component 115 (integrate trace output) , analysis and reporting component 120, data collection 
component 130 [0030], The workflow engine component 1 14 provides a mechanism for 
defining steps and or sequences of steps that the ISA may take in response to a given event 
detected in association with a monitored element. 
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Per claim 19: 

-a client program including the client agent. 

Nguyen: [0049], client agents for client device (client program) 

Per claim 20: 

-an application program including the server agent. 
Nguyen: [0046-0048], server agents for server device 

Claim Rejections - 35 USC § 103 

8. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 

obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are 
such that the subject matter as a whole would have been obvious at the time the invention was made to a person 
having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the 
manner in which the invention was made. 

9. Claim 3 is rejected under 35 U.S.C. 103(a) as being unpatentable over US Patent 
Application Publication 2004/006473 1A1 to Nguyen et al, in view of US Patent Application 
Publication 2003/0005111 Al to Allan. 

Per claim 3: 

Nguyen failed to explicitly disclose: 

-instructions to provide the agent further comprise instructions to employ JavaScript code. 
However Allan disclosed: 
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(Abstract) Monitoring service time in a computer network, including response time for a uniform 
resource identifier request received from a client machine. [0033] All three of these methods 
take advantage of the cookie present in each request originating from an instrumented container 

page; that is, a page containing the QoS JavaScript agent. The cookie is data stored on a client 

o 

computer and used by web sites to keep track of a user's patterns and preferences. The cookie is 
a key that can be used to impose the notion of a session on a series of otherwise disparate 
requests. Each method creates a table of key/value pairs, where the key is the cookie inserted 
into the Hypertext Transport Protocol (HTTP) request header and the value is the time stamp 
signifying when the service time for a given Uniform Resource Identifier (URI) is complete. 
[0041] Referring to FIG. 4.. .Upon receiving the response stream from the origin server (step 
403), the reverse proxy will instrument a valid response stream with the JavaScript agent and 
respond to the original client request with this instrumented response stream (step 404). The 
instrumentation contains the original Tl value as well as the service time taken for the container 
page. As the page is received at the client, the browser parses the page and issues a request for 
each of the URIs that make up the presentation of the page, which are generally the images 
contained on the page (step 405). As each request is received by the QoS agent, i.e. either the 
reverse proxy or some other agent (such as a web server plug-in), the agent searches for the 
JavaScript-inserted cookie in the request headers and creates a new table entry using the value of 
this cookie as the key in the table, if the key does not already exist (step 406). The QoS agent 
then forwards the request to the origin server (step 407). When the origin server responds with 
the resource (step 408), the QoS agent marks the time of the response T2, updates the table 
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entry value with this time stamp, and responds to the requesting client (step 409). . .The 
difference between this value and the Tl value of the transaction record is the service time for 
the transaction. 

Therefore, it would have been obvious, to one of ordinary skill in the art, at the time of the 
invention, to modify Nguyen, using the teachings of Allen, because one would understand that 
monitoring service time in a network of devices would trigger an event rule should the system 
not be properly operating. Sending Javascript in browser code is a known technique for 

communication protocol. 

c 

Conclusion 

10. The prior art made of record and not relied upon is considered pertinent to applicant's 
disclosure. 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Mary Steelman, whose telephone number is (571) 272-3704. The 
examiner can normally be reached Monday through Thursday, from 7:00 AM to 5:30 PM If 
attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Wei 
Zhen can be reached at (571) 272-3708. The fax phone number for the organization where this 
application or proceeding is assigned: 571-273-8300. 

Any inquiry of a general nature or relating to the status of this application should be 
directed to the TC 2100 Group receptionist: 571-272-2100. 
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Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). 



03/29/2007 



Mary Steelman 




